Apps & Consumer
Microsoft patches critical zero-day bugs in Windows and Office
Microsoft has released security patches for critical zero-day vulnerabilities in Windows and Office that are currently being actively exploited by hackers to plant malware.
Microsoft has released security fixes for critical zero-day vulnerabilities affecting its Windows operating system and Office software suite. The company disclosed that these vulnerabilities are actively abused by hackers to plant malware and gain unauthorized access to affected systems. The security update addresses multiple vulnerabilities, including at least two flaws that can be exploited by tricking a user into clicking a malicious link on a Windows computer. According to independent security reporter Brian Krebs, Microsoft also patched three other zero-day bugs in its software that were being actively exploited by hackers.
One of the primary vulnerabilities, tracked as CVE-2026-21510, is a Windows shell bug that allows hackers to bypass SmartScreen, Microsoft’s built-in security feature for screening malicious links. Security expert Dustin Childs stated that this vulnerability can be abused to remotely plant malware on a victim’s computer. While the exploit requires a user to click a link or a shortcut file, Childs pointed out the unusual severity of the flaw. According to Childs, “Still, a one-click bug to gain code execution is a rarity.”
Another vulnerability, tracked as CVE-2026-21513, was discovered in MSHTML, Microsoft’s legacy browser engine. Microsoft noted that this bug similarly allows hackers to bypass Windows security features to plant malware on target systems.
A Google spokesperson confirmed that the Windows shell bug is under “widespread, active exploitation.” The spokesperson warned that the vulnerability allows for the silent execution of malware with high privileges, “posing a high risk of subsequent system compromise, deployment of ransomware, or intelligence collection.” The vulnerabilities were discovered with assistance from security researchers at the Google Threat Intelligence Group. Microsoft noted that details of how to exploit the bugs have been published, potentially increasing the chance of hacks.
Why it matters
These vulnerabilities represent a significant security risk because they allow for one-click exploitation, enabling attackers to bypass standard protections and deploy malware or ransomware on compromised systems.